
Senior Incident Response Engineer
Posted Jun 25

Posted Jun 25
This is a fully remote position, open to applicants in Romania.
• Leverage Sophos technologies to investigate, manage, and respond to cybersecurity incidents.
• Provide mentorship to incident response analysts and MDR operations analysts through technical guidance, review, and escalation support.
• Conduct advanced analyses of incidents to identify initial access, persistence, and lateral movements to effectively contain and remediate threats.
• Engage with MDR customers and MSPs via phone calls and meetings to discuss cyber incidents, often offering priority recommendations for containment, neutralization, and remediation.
• Analyze cyber incidents related to malware, ransomware, and other prevalent attack types.
• Ensure accurate and comprehensive documentation is maintained for analyses conducted during cyber incidents.
• Collaborate closely with internal SophosLabs, Detection Engineering, and Threat Hunting teams to consistently enhance detection logic.
• Partner with Sophos MDR Operations teams to deliver response, remediation guidance, and exceptional customer service.
• When relevant, contribute insights to Sophos blogs, social media, and other platforms regarding adversary tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and additional investigative findings.
• Assess new technologies and processes to bolster the overall incident response capability.
• Aid in the creation of precise and detailed technical incident reports as post-incident deliverables for MDR customers and MSPs.
• A minimum of 4 years of experience in conducting cybersecurity investigations methodically and examining threats, or at least 2 years of experience in incident response engagements.
• Familiarity with network architecture and IT infrastructure.
• Proven experience in creating technical documentation and reports for customers.
• Capability to perform under high-pressure situations where response times are critical to disrupting adversary activities.
• Experience in network and endpoint investigations (macOS, Linux, Windows); knowledge of IDS, IPS, EDR, and basic malware analysis.
• Proficiency in at least one of the following: OSQuery, SQL, or KQL.
• Experience utilizing frameworks such as MITRE Attack and Cyber Kill Chain.
• Willingness to work some weekends and holidays.
• Knowledge of command and script interpreters for Windows and Linux.
• Possession of advanced cybersecurity certifications (GCFE/GCFA, CompTIA CySA+, OSCP, etc.).
• Experience in customer interactions, delivering outstanding customer service.
• Contributions to publications, either authored or acknowledged, within the cybersecurity domain.
• Our team – we foster innovation and creativity, all while cultivating a fun and collaborative atmosphere.
• Employee-led diversity and inclusion networks that enhance community building and provide education and advocacy.
• Annual charity and fundraising initiatives, along with volunteer days for employees to support local communities.
• Global employee sustainability programs aimed at reducing our environmental impact.
• Worldwide fitness and trivia competitions to keep our minds and bodies engaged.
• Global wellbeing days for employees to unwind and recharge.
• Monthly wellbeing webinars and training sessions to promote employee health and wellness.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.